CVE-2026-22662 identifies a blind server-side request forgery (SSRF) vulnerability in the Wiro media generator used by prompts.chat prior to commit 1464475. This flaw allows authenticated users to force the server to make requests to user-controlled URLs via the /api/media-generate endpoint. With a CVSS score of 4.3 (Medium), this vulnerability can be exploited over the network with low complexity to probe internal networks, access internal services, and exfiltrate data, despite not receiving direct response bodies. There is currently no evidence of active exploitation, public exploit code availability (e.g., Metasploit, Nuclei), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026-03-24CPE matchmatch criteria | cpe:2.3:a:fka:prompts.chat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.